Flaw in Ipswitch Collaboration Suite

Opinion
Mar 14, 20054 mins

* Patches from Gentoo, Fedora Legacy * News Rbots, Windows worms

Today’s bug patches and security alerts:

iDefense warns of flaw in Ipswitch Collaboration Suite

The IMAP daemon in the Ipswitch Collaboration Suite is vulnerable to buffer overflow, according to a warning from security experts at iDefense. An attacker could exploit this to run arbitrary code on the affected machine with administrator account privileges. For more, go to:

iDefense advisory:

https://www.nwfusion.com/go2/0314bug1a.html

Fix from Ipswitch:

https://www.ipswitch.com/Support/ICS/updates/im815hf1.html

**********

Gentoo patches Ethereal

The Ethereal protocol analyzer tool is vulnerable to a number of security flaws. These flaws could be exploited to run arbitrary code on the affected system. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-16.xml

Gentoo issues fix for libXpm

According to an alert from Gentoo, “A new vulnerability has been discovered in libXpm, which is included in X.org, that can potentially lead to remote code execution.” For more, go to:

https://security.gentoo.org/glsa/glsa-200503-15.xml

Gentoo fixes buffer overflow in libexif

A buffer overflow in the way libexif, a tool for editing EXIF image data, handles certain user input could be exploited to run malicious code on the affected machine. For more, go to:

https://security.gentoo.org/glsa/glsa-200503-17.xml

**********

Fedora Legacy patches php

Fedora Legacy is fixing the fix for PHP. The original update aimed to fix a number of security vulnerabilities in the popular scripting language. But that update may cause segfault problems in certain versions of Red Hat Linux. The new update fixes that problem. For more, go to:

https://www.nwfusion.com/go2/0314bug1b.html

**********

Today’s roundup of virus alerts:

W32/Rbot-XE — Yet another Rbot variant that spreads via network shares and allows backdoor access via IRC. It drops “mcafee32.exe” in the Windows System folder and can change the login properties for accounts on the infected machine. (Sophos)

W32/Rbot-XI — This Rbot variant attempts to exploit a number of known Windows vulnerabilities as it spreads via network shares. It installs “cthelper.exe” in the Windows System directory, can disable security programs and can be used for a number of malicious activities. (Sophos)

W32/Rbot-XM — This variant drops “CMD16.EXE” in the Windows System folder and can be used to log keystrokes. (Sophos)

W32/Domwis-H — This Windows worm spreads through network shares, dropping “WINFRW.EXE” on the infected machine and allowing backdoor access via IRC. It can be used to steal local information from the target machine and run executables. (Sophos)

W32/Agobot-QT — Another worm that spreads via a network share and allows backdoor access with IRC. It drops the file “super.exe” in the Windows System folder and can be used for a number of malicious tasks. (Sophos)

W32/Agobot-QU — This Agobot variant exploits a number of Windows vulnerabilities to spread via network shares. It disables security applications and can be used for a number of malicious purposes. (Sophos)

W32/Sumom-B — A Windows Messenger worm that attempts to get a user to download a file that looks like an image file but has a .pif attachment. It terminates security-related applications running on the infected machine and prevents access to security Web sites by modifying the Windows HOSTS file. (Sophos)

Troj/Bancos-AS — A worm that attempts to steal account information from Brazilian banking sites. No word on how it spreads. (Sophos)

W32/Elitper-C — A worm that copies itself into files that look like standard Windows system applications (i.e., taskmanager.exe). It disables access to certain Web sites by modifying the Windows HOSTS file and can be used for other malicious tasks. (Sophos)

W32/Sdbot-VW — This Sdbot variant installs “msmonk32.exe” in the Windows System folder and allows backdoor access to the infected machine via IRC. It can be used to steal game CD keys, launch DDoS attacks and other malicious activities. (Sophos)